Hugo v0.163.1 is a security-focused patch release. The majority of fixes address security issues, including an upstream fix in golang.org/x/image (bumped from 0.41.0 to 0.42.0), normalization of integer IPv4 host encodings in HTTP URL checks, and dropping symlinks in several os.* functions to prevent path traversal-style issues. A bug fix for multi --renderSegments merge behavior and a convert command fix are also included. The maintainer notes an uptick in security reports driven by AI tools probing Hugo's security model, not a regression in Hugo's security posture.
326 Impressions